pypi

secmeasure @0.1.2

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC

Malicious

OSV ID

MAL-2025-47452

Ecosystem

pypi

Summary

This package installs the SilentSync remote access trojan and allows remote code execution and data exfiltration. Windows machines are targetted by this malicious package.

Source: google-open-source-security (f566db2e1359b455ca36524d9c066854754e71ac92deca9706f69d3d71cc8414)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.